Posts Tagged Zeus bot
Zeus baddies unleash nasty new bank Trojan
Posted by Mourad Ben Lakhoua in News on July 14, 2010

Hackers have created a new version of the Zeus crimeware toolkit that’s designed to swipe bank login details of Spanish, German, UK and US banks.
The malware payload, described by CA as Zeus version 3, is far more selective in the banks it targets. Previous versions targeted financial institutions around the world while the latest variant comes in two flavours: one that only target banks in Spain and Germany, and a second that only targets financial institutions in the UK and US.
In addition the latest version of Zeus contains features that makes it far harder for security researchers to figure out what the malware is doing. Zombie drones on the Zeus botnet operate on a need to know basis, CA explains.
“In earlier versions, Zeus handles this configuration file in a way that security researchers can easily manage to reverse engineer and capture the actual full configuration content,” writes Zarestel Ferrer, a senior research engineer with CA’s Internet Security Business Unit.
“This is no longer the case for the latest Zeus bot version 3, which is already in the wild.
“It employs layers of protection by applying the principle of least privilege. It means that the bot must only access remote command, information and resources that are necessary to a specific function and purpose.”
Command and control systems associated with the bot are “mostly hosted in Russia”, according to CA. Banks in Spain, UK, USA and Germany were the most targeted institutions in previous versions of the banking Trojan.
The unknown cybercrooks have tightened this focus with the latest version of the cybercrime toolkit, meeting customer demand in a manner akin to legitimate software developers releasing localised versions of tools in key geographical markets.
[Source: The Register]
Malware is Hiding in Amazon Cloud
Posted by Mourad Ben Lakhoua in Cloud Computing Security, Cybercrime & Hacking, News on December 12, 2009
Cybercriminals have made this week unforgettable for Amazon team this is after that security researchers have reported existing of Zeus Botnet at The cloud-based EC2 (Elastic Compute Cloud) control center.
The incident has been detected after a Password-stealing Zeus banking Trojan had infected client computers where hackers were able to compromise a site on EC2 and use it as their own command and control operation.
Methusela Cebrian Ferrer, senior researcher at CA, said in a blog post the following:
“The group behind this criminal activity is obviously doing it for financial gain – stealing both your identity and your money,” Ferrer stated. “In this variant, we have learned how cloud on-demand pay-as-you-use — offerings could be used to fuel such online cybercrimes.”
After this Incident Amazon should review their entire environment to be sure that they provide a minimum level of security for their customers.
We are also detecting a big concentration on the Cloud based solution in the last time. Moxie Marlinspike has started a new WiFi (WPA) password cracking service hosted in the cloud. Password cracking system is based on comparing the hash from a WiFi AP against 135 million possibilities in 40 min.
make sure you subscribe to my RSS feed!


Latest Comments